Skip to content

sabbaperveen/IBM-Qradar

Folders and files

NameName
Last commit message
Last commit date

Latest commit

Β 

History

3 Commits
Β 
Β 
Β 
Β 

Repository files navigation

IBM QRadar Learning Repository

This repository contains study materials, guides, and documentation for IBM QRadar 7.5 Community Edition (CE).
It covers installation, log integration, rules, offense management, and advanced administration topics.

1. Introduction to SIEM & QRadar

  • What is SIEM?
  • IBM QRadar Overview
  • QRadar Components

2. IBM QRadar 7.5 CE Installation

  • Prerequisites
  • Download QRadar 7.5 CE ISO
  • Create & Configure a VM in VMware Workstation
  • Install QRadar from ISO
  • Accessing the QRadar Web Interface
  • Post-Installation Configuration

3. License Management

4. Log Forwarding

  • Sending Windows Logs using WinCollect
  • Sending Linux Logs via Syslog

5. Rules & AQL

  • Creating and Testing Rules
  • Using Search Filters
  • Ariel Query Language (AQL)

6. Offense Management & Investigation

  • Understanding Offenses
  • Investigating Offenses
  • Reviewing Triggered Rules

7. Reference Sets & Maps

  • Creating and Populating Reference Sets
  • Using Reference Sets in Rules

8. QRadar Apps & Extensions

  • Installing & Using QRadar Apps
  • Enriching Offense Data

9. DSM Editor & Log Source Extensions

  • Custom Parsing
  • Creating Log Source Extensions
  • Extracting Custom Properties

10. Use Case Manager (UCM)

  • Adding Authorized Services Tokens
  • Creating Building Blocks and Rules

11. Administration

  • Event Processor Configuration
  • Network Hierarchy Setup
  • Event Retention & Backup
  • Log Source Management
  • XPath Queries, Event Coalescing, and Groups
  • Report Creation & Notifications

12. Conclusion


🎯 Purpose

  • Provide structured documentation for IBM QRadar 7.5 CE.
  • Help with installation, log forwarding, rules creation, and administration.
  • Serve as a quick reference for security students and professionals.

πŸ“Œ How to Use

  1. Browse the repository and open PDF guides.
  2. Follow step-by-step instructions for setup and configuration.
  3. Use as reference material for QRadar learning and labs.

⭐ This repository is for educational and reference purposes only.

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

 
 
 

Contributors